logo

U.S. CISA adds Ivanti EPM, SolarWinds, and Omnissa Workspace One flaws to its Known Exploited Vulnerabilities catalog

ID: bfa8729d-7039-5b37-99ba-ac7a25470faf

STIX ID: report--bfa8729d-7039-5b37-99ba-ac7a25470faf

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-03-10

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog — an Omnissa Workspace ONE SSRF (CVE-2021-22054, CVSS 7.5), a SolarWinds Web Help Desk deserialization vulnerability enabling RCE (CVE-2025-26399, CVSS 9.8), and an Ivanti Endpoint Manager authentication bypass allowing credential leakage (CVE-2026-1603, CVSS 8.6) — and ordered federal agencies to apply fixes by set deadlines; organizations are advised to review the catalog and patch affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.